Large influx of blacklisted IP

Status
Not open for further replies.

jmatano

Platinum Partner
Advanced Certified
Joined
May 31, 2018
Messages
103
Reaction score
22
Hey all. Our on prem install has been getting bombarded with blacklisted IP’s from what is identifying as a Polycom on our SIP service. It started around Friday and continuing today.

Is there something we can do about this? Has something been going on with other clients causing the massive uptick the past couple of days? Our system uses 3CX dns and a static IP.
 
Its pretty common to see the 3CX security doing its job. We see a fair bit of this.

In the early days we only allowed UK IP through our firewalls but then hackers started using UK VPS

To really bolster up security on sites where you don't use the app, you can change your inbound firewall rule to the IP of your SIP trunk server as apposed to ANY. If you have remote workers using webclient, issue them a VPN.

Obvious usual security steps; lock down management console to select IP, password protect 3CX backup, disable remote STUN on any extensions that don't absolutely need it, increase the blacklist time.
 
i have noticed that the our "Blacklist time interval" is set to 30 days yet the notification email say the IP was blacklisted for 15 mins only.. not sure if its a bug? that would be why you are seeing more breakin attempts as the system is not blacklisting the IP for long enough so the bad guys keep trying..
 
I have mine set at: 86400 (24 hours)
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet